I know Mastodon hates LLM's and AI. So here goes!

I recently got access to trusted access of cyber capabilities of both openai and anthropic, which also allows you to weaponize security vulnerabilities.

The speed at which these parrots can find bugs and be creative enough to exploit them is staggering.

I recently pointed an LLM at an kernel fix that was reachable by an unprivileged namespace on Debian and it fully weaponized it, without too much me prompting it in the right direction, in about 7-9 hours.

I don't think open-source and companies will know what's coming for them once these open-source weight models will have broader reach and get better at exploiting vulnerabilities on a massive scale as anyone can access them.

The bottom line I think is, you cannot patch faster than the attackers can easily chain all kinds of vulnerabilities together and just move laterally on an incredibly fast pace.

I've started reporting vulnerabilities to all kinds of projects and the majority have trouble or patching issues found. There's not enough maintainers, or there's simply none anymore.

I've been getting quite worried about what our future will look like for data privacy. I think outright not running an LLM over your codebase to find critical security vulnerabilities because of your moral stance will keep us more insecure.

Please run an LLM over your code base if it's internet facing or something critical, we thank you!

Can't wait for the discussions on this!

Replying to @⁨drwhax@infosec.exchange⁩

@drwhax Look, many people have different reasons to be against AI.

Mine is a very specific position against vibe coding, generative AI and ghoulish tech bros and their wannabes wanting to actively destroy excellence, art, nature and human work.

If you have a tool that does not contradict these specifics, then I have no issue. A static analyser ML-like code tool that works on premises, doesn't make a tech bro richer and dry a lake? This is OK for me (and I suspect, the future or much of this)

Replying to @⁨glitchypixel@mastodon.gamedev.place⁩

@drwhax But are you maling a tech bro richer to vibe code everything you do and just pressing Y without thinking, wasting tokens as much as possible because who cares? I have beef.

Are you actively (and disgustingly so), trying to replace every human in the loop just to create ghibli styled art slop or disgusting political videos so you can further your agenda? I have beef.

Are you actively numbing your brain, stop thinking about anything and becoming a reverse centaur on purpose? I have beef.

en

Replying to @⁨glitchypixel@mastodon.gamedev.place⁩

@drwhax I personally dont and will never vibe code because, in a very personal position, I love my brain and I like to think, and a brain without friction will cease to function (use it or lose it).

I love people making art (and yes, this includes code). And I deeply hate the contempt for people paying a tech bro to use genAI to dismiss and degrade those artists with a sort of vindictive glee, especially since most artists are already treated so badly. It is disgusting.

Replying to @⁨glitchypixel@mastodon.gamedev.place⁩

@drwhax But I don't mind the underlying tech as much as I dont have a beef against the, let's say Microsoft Kinect (a tool made in essence the same way).

So are you getting a Chinese open weight, AI (people won't say it, maybe because of fear of retaliation from the US, but most companies will do this) stuffing it in your server and having 90% effectiveness to find vulnerabilities and doing static analysis in code locally?

That sounds like an actual use case. Just one the tech bros don't like.